Dev News Daily ENDE

GuardDuty Runtime Monitoring moves into the Security Hub Threat Analytics bill

AWS has folded Amazon GuardDuty Runtime Monitoring into the Threat Analytics plan of AWS Security Hub, according to an announcement on 2 October. The change is about billing, not detection.

Runtime Monitoring is the part of GuardDuty that looks inside running workloads - processes, network connections and file changes - for signs of attacks such as a container breaking out to its host, an attacker gaining higher privileges, or a crypto miner. It covers virtual machines on EC2, Kubernetes clusters on EKS and containers on ECS with Fargate. Until now that coverage was billed as GuardDuty usage. In any account and region where Security Hub is switched on, the GuardDuty line for it now disappears and the cost moves to the Security Hub bill, where it is counted as one usage type for all three compute services instead of one charge per resource type.

AWS says detection coverage, finding types and the GuardDuty security agents all stay the same, and nothing has to be reconfigured. Two caveats are spelled out. The free trial for the Threat Analytics plan remains separate from the free trial for the Security Hub Essentials plan, and the change does not add a new free trial for Runtime Monitoring. AWS points customers to Cost Explorer or the Security Hub usage page to see how their bill is affected.

GuardDuty Runtime Monitoring moves into the Security Hub Threat Analytics bill
GuardDuty Runtime Monitoring moves into the Security Hub Threat Analytics bill — Dev News Daily

Why it matters

For teams that already pay for Security Hub, one line item on the bill disappears and another grows, with the metering simplified to one usage type. Cost dashboards and budget alerts keyed to GuardDuty Runtime Monitoring charges will need updating, because those charges will drop to zero for covered accounts without anything having been switched off.

Written by Victoria Shinder.